Know when someone changes a site

See which WordPress user installed, removed or switched a plugin or theme, or added an admin, and get an email the moment it happens.

Updated Oct 7, 2026

Clients, their staff and other developers can still sign in to wp-admin and change things. With WP Foreman plugin 0.7.0 or newer, every one of those changes goes in the site’s log with the person’s name, and you can get an email the moment it happens. They don’t need a WP Foreman account.

Jane Doe installed the plugin Hello Dolly
Jane Doe ([email protected]) · editor · 203.0.113.9

How it looks in the log

What’s recorded

Change In the log Emailed right away
Plugin installed, deleted, activated or deactivated Yes Yes
Plugin updated Yes No (it’s in the log)
Theme installed, deleted or switched Yes Yes
Theme updated Yes No
WordPress updated by hand Yes Yes
A new administrator account (created, or someone made an admin) Yes, in red Yes
An administrator signed in to wp-admin Yes (under Sign-ins) No
WordPress auto-updates Yes, as “WordPress auto-update” No

Changes you make through WP Foreman are logged under your name already, so they’re never counted as “outside” changes.

Who and how

For each change the log shows the WordPress user’s name, email and role, the IP address it came from, and how it happened: in wp-admin, through WP-CLI (the command line), by a WordPress auto-update, by a scheduled task on the site, or through the WordPress REST API. Click the entry for the full details.

How fast

The site tells WP Foreman as soon as the change is made, usually within seconds. If WP Foreman can’t be reached at that moment, the site keeps the event and sends it with the next check (about every 30 minutes). Nothing is lost if a message fails.

Emails

You get one email per site per batch of changes, titled “Heads up: …”, listing what changed, who did it and when, with a link to the log. Turn these on or off in Settings › Notifications. They’re on by default.

Want them somewhere else? The site.changed webhook sends the same changes to Slack (through Zapier or Make) or your own system.

Changes WordPress can’t name

If files are changed directly on the server (FTP, the host’s file manager, a deploy script), WordPress doesn’t know who did it. WP Foreman still notices the change at its next check and logs it as “made on the site, outside WP Foreman”, without a name.

Privacy

To show who made a change, WP Foreman stores the WordPress user’s name, email, role and IP address with that log entry. It never sees or stores WordPress passwords. See What data WP Foreman stores.

Needs WP Foreman plugin 0.7.0 or newer. Changes are only recorded from the moment the site has 0.7.0. Update from the site’s Overview (see Update the WP Foreman plugin).

Was this helpful?